CVE-2026-50259 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexing
Information published.
Categories: Microsoft
CVE-2026-50260 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter()
Information published.
Categories: Microsoft
CVE-2026-50262 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes
Information published.
Categories: Microsoft
CVE-2026-50256 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatch
Information published.
Categories: Microsoft
CVE-2026-50261 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter()
Information published.
Categories: Microsoft
CVE-2026-10879 DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders
Information published.
Categories: Microsoft
CVE-2026-40930 LIBPNG: Chunk smuggling in push-mode APNG parser via unconsumed chunk body
Information published.
Categories: Microsoft
CVE-2026-50265 Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292
Information published.
Categories: Microsoft
CVE-2026-49975 Apache HTTP Server: mod_http2 denial of service
Information published.
Categories: Microsoft
CVE-2026-11463 USCiLab Cereal Shared Pointer type confusion
Information published.
Categories: Microsoft
CVE-2026-35429 Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
Updated an acknowledgement. This is an informational change only.
Categories: Microsoft
CVE-2026-33118 Microsoft Edge (Chromium-based) Spoofing Vulnerability
Updated an acknowledgement. This is an informational change only.
Categories: Microsoft
CVE-2026-7774 tarfile.data_filter path traversal bypass allows writing outside the extraction directory
Information published.
Categories: Microsoft
CVE-2026-3276 Potential DoS via quadratic complexity in unicodedata.normalize()
Information published.
Categories: Microsoft
CVE-2026-8643 pip can extract console_scripts and gui_scripts outside installation directory
Information published.
Categories: Microsoft
CVE-2026-8829 HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities
Information published.
Categories: Microsoft
CVE-2026-43958 Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial of service
Information published.
Categories: Microsoft
CVE-2026-5419 Guntls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal
Information published.
Categories: Microsoft
CVE-2026-27145 Inefficient candidate hostname parsing in crypto/x509
Information published.
Categories: Microsoft
CVE-2026-42507 Arbitrary inputs are included in errors without any escaping in net/textproto
Information published.
Categories: Microsoft


